Subprocessors
OnSyra · Version 1.0 · DRAFT — to be completed as vendors are contracted
Third parties that process personal data on our behalf. Referenced by the Privacy Policy §4. We give 30 days' notice before adding one.
Current
| Purpose | Provider | Data | Location |
|---|---|---|---|
| Hosting and compute | Self-hosted (Ubuntu, Apache, MySQL) | All platform data | United States |
| Email delivery | Self-hosted Postfix, DKIM-signed | Email addresses, message content | United States |
| Map tiles | CartoDB / OpenStreetMap | Coarse coordinates only — tile requests, never user identity | EU / United States |
| Front-end libraries | cdnjs, jsDelivr, unpkg, Google Fonts | IP address of the browser requesting the asset | Global CDN |
To be contracted — none of these is live yet
| Purpose | Candidates | Data it would receive |
|---|---|---|
| Identity verification (KYC/KYB) | Persona, Alloy, Middesk | Name, DOB, address, ID document, taxpayer ID |
| Sanctions and PEP screening | ComplyAdvantage, Sanction Scanner | Name, DOB, country |
| ACH / payment processing | Dwolla, Stripe, Modern Treasury | Name, bank details, transaction data |
| Bank account verification | Plaid | Bank credentials (via their own flow — never touching LCS) |
| Background checks | Checkr, Sterling | Name, DOB, SSN, address history |
| SMS delivery | Twilio, MessageBird | Phone number, message content |
| Error monitoring | Sentry | Stack traces, user id, request metadata |
| Object storage | AWS S3 or equivalent | Uploaded files including identity documents |
Standards every subprocessor must meet
- A written data processing agreement, with Standard Contractual Clauses where data leaves the EU/UK
- Security controls at least equivalent to ours
- Breach notification to us within 24 hours
- Deletion or return of data on termination
- No use of our users' data for their own purposes
- Sub-subprocessors disclosed and approved
Deliberately absent
No advertising, analytics or behavioural tracking subprocessors. The platform carries no third-party trackers. This is a design decision, and the Content Security Policy enforces it — an advertising script could not load even if one were added by mistake.